Integer Overflow in LibRaw Affects Image Processing Capabilities
CVE-2026-24450

8.1HIGH

Key Information:

Vendor

Libraw

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-24450?

An integer overflow vulnerability has been identified in the uncompressed_fp_dng_load_raw function of LibRaw. When triggered by a specially crafted malicious file, this vulnerability can lead to a heap buffer overflow, allowing attackers to exploit the system by providing such files. It is crucial for users of LibRaw to assess their usage and implement necessary security measures to mitigate potential risks associated with this vulnerability.

Affected Version(s)

LibRaw Commit 8dc68e2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Francesco Benvenuto of Cisco Talos.
.